This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Espionage, Foreign Interference and Cognitive Warfare: The New Reality

Download resources

About this session

Michel Juneau Katsuya, former head of CSIS's Asia-Pacific counter-espionage unit, argues that most organizations never do a rigorous threat and risk assessment, offering a simple formula: threat to (what needs protecting) plus threat from (who is targeting it) equals a real vulnerability assessment, replacing a shotgun approach with a sniper one. Drawing on a 1995 CSIS study he commissioned, he estimates Canada loses roughly 10 to 12 billion dollars a year to intellectual-property theft, extrapolating from later FBI figures to 100-120 billion today, and argues Canada is a prime target because it is knowledge-based, resource-rich, sits at major international tables, and is poorly protected legally. He profiles five threat agents: state-sponsored spies, with China's patient mass-collection approach contrasted against a smash-and-grab style used by others, company-versus-company espionage such as a European slush fund used for bribery, organized crime, insider threats (roughly 80% of espionage cases involve someone with legitimate access), and activists. He closes urging security teams to shift from an alarmist to a strategic, profitability-focused discourse to avoid being treated as a cost center.

Key takeaways

  • Use the formula 'threat to' (what you need to protect) plus 'threat from' (who is targeting it) to move from a scattershot security budget to a targeted, sniper-like one.
  • Reframe security reporting from alarmist warnings to a profitability argument; leadership treats a purely alarmist security function as a cost center to be cut.
  • Treat insider risk as the largest single category: a large share of espionage cases involve someone with legitimate, already-granted access, not an external break-in.
  • Watch for mass, low-cost intelligence-gathering tactics disguised as normal business activity, such as sham recruitment trips or interviews designed to extract R&D status from junior candidates.
  • Investigate suspicious patterns, not isolated incidents, such as repeatedly losing competitive bids to the same foreign competitor by a narrow margin; unexplained losses can indicate leaked information.

Speakers

Michel Juneau Katsuya
Michel Juneau Katsuya
President and CEO · The Northgate Group Corp

Resources

Tags

More from GoSec 2023

Also from Michel Juneau Katsuya

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.